PT-2023-1972 · Apache+6 · Apache Openoffice+7

CVE-2022-38745

·

Publicado

2023-03-24

·

Atualizado

2025-02-13

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions before 4.1.14
Description The issue is related to the possibility of adding an empty entry to the Java class path in Apache OpenOffice. This could allow a remote attacker to execute arbitrary Java code from the current directory by loading a specially crafted java file.
Recommendations For versions before 4.1.14, update to version 4.1.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the Java class path to minimize the risk of exploitation.

Exploit

Correção

Uncontrolled Search Path Element

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:6508
ALSA-2023:6933
BDU:2023-01592
CESA-2023_6933
CVE-2022-38745
DLA-3526-1
RHSA-2023:6508
RHSA-2023:6933
RHSA-2023_6508
RHSA-2023_6933
USN-6023-1

Produtos afetados

Almalinux
Apache Openoffice
Astra Linux
Centos
Linuxmint
Openoffice
Red Hat
Ubuntu